Re: Find out the subnetting of a company

From: Tony Carter (tcarter_at_entrusion.com)
Date: 07/22/04

  • Next message: Gerry Eisenhaur: "Re: Website search engine is a hacking tool.."
    Date: Wed, 21 Jul 2004 20:44:56 -0400
    To: "David M. Zendzian" <dmz@dmzs.com>
    
    

    ICMP type 18, Address mask reply message is generated in response to
    an ICMP type 17, Address mask request message.

    ICMPush at packetstorm or http://www.angio.net/security/icmpquery.c

    -Tony

    On Jul 20, 2004, at 12:53 PM, David M. Zendzian wrote:

    > Isn't there some icmp or ip based packet that can be sent to most
    > devices querying the subnet theyare in? I am on vacation with only
    > blackberry and can't google it, but someone out there must be familiar
    > with that??
    > -----Original Message-----
    > From: "Dieter Sarrazyn" <dsr@ascure.com>
    > Date: Tue, 20 Jul 2004 08:38:42
    > To:<il.prof@virgilio.it>, <pen-test@securityfocus.com>
    > Subject: RE: Find out the subnetting of a company
    >
    > Hi,
    >
    > You can find lot's of the subnet structure with ping & traceroute scans
    > already. First, you can use the ping functionality of nmap (nmap -sP)
    > which should give you information about network and broadcast
    > addresses.
    > If you found these parts, you already know how the subnetting is done.
    > With traceroute, you'll find out how these subnets are connected to
    > eachother.
    >
    > Of course, if there's a router that has snmp enabled, try to find one
    > of
    > the community strings & dump the routing table of this router...
    >
    > Hope this helps.
    >
    > regards,
    > Dieter
    >
    >> -----Original Message-----
    >> From: il.prof@virgilio.it [mailto:il.prof@virgilio.it]
    >> Sent: donderdag 15 juli 2004 10:17
    >> To: pen-test@securityfocus.com
    >> Subject: Find out the subnetting of a company
    >>
    >> During an internal black-box penetration test, from a subnet
    >> of a company (with or without DHCP), how do you find out the
    >> structure of the other subnets of network? In particular, how
    >> do you determine/discover the subnetting of the IP space of a company?
    >>
    >> An example:
    >>
    >> - IP network of the company XYZ: 10.0.0.0/8 (I use a private
    >> class to avoid the use of a real address space)
    >> - I?m in the subnet 10.0.0.0/24
    >>
    >> How do you find out the structure of other subnets that are
    >> part of the network 10.0.0.0/8?
    >>
    >> Il Prof.
    >>
    >>
    >>
    >>
    >
    >
    >
    > /--------------------------------------\
    > David M. Zendzian * dmz@dmzs.com
    > (415) 867-7812 - phone
    > -------------
    > Imagination is greater than knowledge * Albert Einstein
    > Every day is a good day, whether you like it or not! *
    >


  • Next message: Gerry Eisenhaur: "Re: Website search engine is a hacking tool.."

    Relevant Pages

    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Pen-Test)
    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Security-Basics)
    • Re: Multiple closed networks and UDP. Please help me.
      ... Note that it makes absolutely no sense to have three identical subnets connected to the ... protocol does not provide any capability for distinguishing network adapters. ... I have worked with TCP many times, but never UDP. ... I believe that the TCP connection will be assigned based on the IP ...
      (microsoft.public.vc.mfc)
    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Pen-Test)
    • Re: Multi NIC Windows 2003 routing problem
      ... You cannot use two IP#s from different subnets on the same NIC unless it is ... > All network traffic destined for the 192.168.20.x and 192.168.90.x should ... (still does, but that server has to go, for obvious reasons). ... >> Microsoft Windows XP - Multihoming Considerations ...
      (microsoft.public.win2000.networking)